---
id: CVE-2026-7774
title: >-
  tarfile.data_filter could be bypassed using crafted link entries, including
  symlinks with empty or directory-like names, to redirect later archive members
  outside the intended extraction directory
summary: >-
  tarfile.data_filter could be bypassed using crafted link entries, including
  symlinks with empty or directory-like names, to redirect later archive members
  outside the intended extraction directory. This allowed a malicious tar
  archive to…
severity: none
cwe:
  - CWE-22
published: '2026-06-04'
updated: '2026-07-07'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-7774'
references:
  - url: >-
      https://github.com/python/cpython/commit/0478bd83d82b255e0f29f613367a59d261e7eaa2
    label: cna@python.org
  - url: >-
      https://github.com/python/cpython/commit/0d28f5e46e151718972dfabd91205444d0037b6d
    label: cna@python.org
  - url: >-
      https://github.com/python/cpython/commit/10a13bee3c24f9c62b602e696334ff2272a40efc
    label: cna@python.org
  - url: >-
      https://github.com/python/cpython/commit/578411982c16f753f4893532510099ef665117da
    label: cna@python.org
  - url: >-
      https://github.com/python/cpython/commit/5cf47a248c35c375d610b87b2f72fd1ed454b558
    label: cna@python.org
  - url: >-
      https://github.com/python/cpython/commit/74cca9a92fb7d653e404843a56b8bdc7b0afdbbf
    label: cna@python.org
  - url: >-
      https://github.com/python/cpython/commit/c063191cb7f9170f9565e305f8aa2b79ab2bf609
    label: cna@python.org
  - url: 'https://github.com/python/cpython/issues/149486'
    label: cna@python.org
  - url: 'https://github.com/python/cpython/pull/149487'
    label: cna@python.org
  - url: >-
      https://mail.python.org/archives/list/security-announce@python.org/thread/4FU62L2M6RMMHT2QPGQNPEHHUND7CEX5/
    label: cna@python.org
  - url: 'http://www.openwall.com/lists/oss-security/2026/06/04/9'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00598
epssPercentile: 0.47369
ingestedAt: '2026-07-07T18:42:24.242Z'
---

## Overview

tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
